CVE-2026-1709Critical· 9.4▾ MidnightA flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network ac…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.7 · likelihood 1.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
5.8%
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents, by connecting without presenting a client certificate.
enterprise_linux = 9.0enterprise_linux = 10.0enterprise_linux_eus = 10.0enterprise_linux_for_arm_64 = 9.0_aarch64enterprise_linux_for_arm_64 = 10.0_aarch64enterprise_linux_for_arm_64_eus = 10.0_aarch64enterprise_linux_for_ibm_z_systems = 9.0_s390xenterprise_linux_for_ibm_z_systems = 10.0_s390xenterprise_linux_for_ibm_z_systems_eus = 10.0_s390xenterprise_linux_for_power_little_endian = 9.0_ppc64leenterprise_linux_for_power_little_endian = 10.0_ppc64leenterprise_linux_for_power_little_endian_eus = 10.0_ppc64lekeylime < 7.12.0Upgrade past the affected range:
keylime 7.12.0Connected by shared product, vendor, weakness, or advisory.
CVE-2022-1053Critical· 9.1Tenant and Verifier might not use the same registrar data
CVE-2023-38200High· 7.5Keylime's registrar vulnerable to Denial-of-service attack via a single open connection
CVE-2023-38201Medium· 6.5Keylime registrar and (untrusted) Agent can be bypassed by an attacker
CVE-2026-58065High· 8.1The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification
CVE-2025-10966Medium· 4.3curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.
CVE-2026-78807High· 7.1wpa_supplicant: wpa_supplicant: Security bypass via missing PMKSA validation (CVE-2026-78807)